Multi-tenant SaaS Access Control via Segmentation and Virtualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Software as a Service (SaaS) architecture faces challenges in providing customization and ensuring security and privacy for customers, as it treats software applications as commodities available to all, lacking flexibility to meet diverse customer needs and potentially compromising security with centralized management across wide customer bases.

Innovation Solution

A system that manages user access to application-specific capabilities by correlating user identifiers with user roles and application-specific capabilities, using a security module to enforce access controls, allowing for customization and enhanced security through selective addition of security and privacy services, creating a virtual private Internet environment for multi-tenant service delivery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If centralized management of SaaS applications is used, then scalability and maintenance are improved, but security concerns and customization limitations worsen

Engineering Contradiction:
ImprovescalabilityVSAvoidsecurity concerns
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the centralized SaaS platform into multiple isolated tenant environments, where each tenant's data and applications are logically separated. This segmentation allows centralized management benefits while preventing security risks from propagating across the entire system, as each tenant operates in an isolated namespace with controlled access to resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization layer as an intermediary between the centralized infrastructure and individual tenants. This virtualization intermediary manages resource allocation, enforces security policies, and provides customization capabilities while maintaining the underlying centralized architecture, thus resolving the conflict between centralized management and security concerns.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If centralized management of SaaS applications is used, then scalability and maintenance are improved, but customization capabilities worsen

Engineering Contradiction:
ImprovescalabilityVSAvoidcustomization
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic configuration capabilities within the virtualized tenant environments, allowing customization of application settings, data models, and user permissions without affecting the core centralized platform. This dynamic approach enables each tenant to adapt the software to their specific needs while maintaining the scalability benefits of centralized management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies local quality by allowing each tenant to have customized configurations, data schemas, and application parameters within their isolated environment, while the overall platform maintains uniform centralized management. This enables customization at the local tenant level without compromising the global scalability and maintenance advantages of the centralized architecture.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If separate application instances are generated for each customer (ASP model), then customization is improved, but maintenance difficulty and scaling complexity worsen

Engineering Contradiction:
ImprovecustomizationVSAvoidmaintenance complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate application instances into a single unified SaaS platform that serves multiple tenants simultaneously. By combining the instances while maintaining logical isolation through virtualization, the system achieves the customization benefits of separate instances without the maintenance complexity and scaling issues of managing multiple independent applications.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8291490B1Tenant life cycle management for a software as a service platform
Publication Date: 2012.10.16 EMC IP HLDG CO LLC
  • US8291490B1 patent drawing
  • US8291490B1 patent drawing
  • US8291490B1 patent drawing

AI summary

Managing user access to application-specific capabilities of a system includes maintaining data correlating application-specific capabilities for each of the applications of the system, where the application-specific capabilities of different applications are independent of each other. Managing user access also includes maintaining data correlating user identifiers with user roles, maintaining data correlating user roles with application-specific capabilities, and managing the data using a security module that accesses the data correlating application-specific capabilities, data correlating user identifiers, and the data correlating user roles. The system may have a plurality of tenants and wherein each of the tenants subscribes to one or more of the applications. Each of the users may correspond to a particular one of the tenants. Each tenant may subscribe to a particular set of applications/features.